Breaking
Cyber CrimeDeveloping Story

Ransomware Operations Surge in July

Ransomware incident counts climbed in July as attackers shifted focus toward financial, technology, and healthcare sectors.

··1 hour ago·2 min read
a close up of a computer in a dark room
Photo by Tyler on Unsplash

Cybersecurity monitoring data indicates a marked increase in ransomware activity throughout July, contrasting with broader industry attention currently fixated on emerging artificial intelligence threats. While digital security discourse has been dominated by concerns over AI-driven exploits, established ransomware groups have maintained a high operational tempo, targeting specific industry verticals with varying degrees of intensity.

Shifting Targets and Sector Trends

Data from UK-based firm Comparitech reveals that ransomware incidents rose by nearly 20 percent in July, totaling 799 recorded events compared to 668 in June. Of these incidents, 51 have been confirmed by the affected victims. This volume marks the second-highest monthly total for the year, trailing only the 805 attacks logged in March.

Analysis of the target landscape shows a distinct pivot in attacker behavior. While recent reports have highlighted cyberattacks targeting water infrastructure, those specific incidents were not classified as ransomware. In fact, ransomware attacks directed at utility companies saw a 44 percent decrease during the month. Similarly, legal firms and government agencies experienced a reduction in targeting, with attack rates dropping 31 percent and 11 percent, respectively.

Sector-Specific Growth

Conversely, threat actors intensified their focus on other industries. The finance, technology, pharmaceutical, medical billing, and education sectors saw significant increases in ransomware activity. Financial firms experienced a 71 percent surge, followed by tech firms at 62 percent, pharmaceutical companies at 46 percent, and the education sector at 44 percent.

These shifts align with findings from reported trends regarding ransom payments. Organizations in manufacturing, education, healthcare, and finance remain the most likely to issue payments to threat actors. Even within the finance sector, which is the least likely of those groups to pay, ransom demands are met in 51 percent of cases.

Geographic Distribution of Attacks

The United States continues to be the primary focus for ransomware operators, accounting for 322 of the 799 attacks observed in July. Germany held the second position with 40 recorded incidents, highlighting the concentrated nature of these campaigns.

  • July ransomware incidents: 799
  • June ransomware incidents: 668
  • U.S. attacks in July: 322
  • German attacks in July: 40
  • Finance sector attack increase: 71 percent
  • Tech sector attack increase: 62 percent

Prolific Gangs and Activity

The threat landscape is currently dominated by two primary actors. The group known as Qilin, responsible for the 2024 attack on pathology provider Synnovis, claimed 125 victims in July. They are competing with a newer entity, The Gentlemen, which claimed 135 victims during the same period. Together, these two organizations accounted for nearly 33 percent of all recorded attacks in July.

While specific ingress methods for these July incidents remain unconfirmed, industry research provides insight into the methodology often employed by such groups. Tactics range from the exploitation of stolen credentials to the abuse of zero-day vulnerabilities.

Implications for Security Posture

The continued success of these campaigns emphasizes that organizations must maintain focus on fundamental security hygiene. The divergence between public interest in AI and the practical reality of persistent, manual ransomware threats suggests that defenders should prioritize core defensive measures. Regular system updates, the implementation of robust multi-factor authentication, and the maintenance of verified, off-site backups remain the most effective defenses against these evolving extortion operations.

#malware#cybercrime#ransomware#security

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories